Database/Control plane, storage & DevOps

Imagination PowerVR GPU driver - cache subsystem information page: The driver's cache-subsystem information page
CVSS 5.5CVE-2022-20235Control plane, storage & DevOpsPowerVR information pagecurated
Impact
The driver's cache-subsystem information page, intended to be writable only by the driver, was mapped writable to userspace before DDK 1.18. A tenant process could alter driver cache state. Included as another instance of the GPU-driver-maps-too-much class that recurs across vendors.
Who can reach it
Unprivileged local application holding the GPU device node.
What to do
Update to Imagination DDK 1.18 or later. Not a datacenter part; treat as vendor-evaluation intelligence rather than a fleet action.
References
Related entries
- Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffers: The software IO TLB leaks information through bounceCVE-2022-48853 · Linux swiotlb - info leak with DMA_FROM_DEVICE bounce buffersMedium
- Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and Windows: The keys LSA usesCVE-2023-4327 · Broadcom LSI Storage Authority (LSA) - on-disk credential/key storage on Linux and WindowsMedium
- Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code): On 64-bit platforms the pfn_to_kaddr() macroCVE-2023-52659 · Linux x86/mm - pfn_to_kaddr() 64-bit input handling (SNP support code)Medium
- Linux perf/x86/amd/core - overflow status not cleared for unhandled indices: Unhandled overflow bits are left setCVE-2023-53073 · Linux perf/x86/amd/core - overflow status not cleared for unhandled indicesMedium
- Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errors: On AMD Zen systems, the InstructionCVE-2023-53438 · Linux x86/MCE - CS register not saved on AMD Zen Instruction Fetch Poison errorsMedium
- Linux i915 GVT-g mediated GPU virtualisation: Unsafe cleanup of per-vGPU debugfs state when a mediated vGPU isCVE-2023-53625 · Linux i915 GVT-g mediated GPU virtualisationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.